LACMA disclosed a breach that exposed customer and employee information after suspicious activity was detected on its systems in July 2025. The museum later determined that attackers may have accessed highly sensitive data, including Social Security numbers, government IDs, financial details, and health information. #LACMA
Keypoints
- LACMA detected suspicious activity on July 11, 2025, that had started four days earlier.
- The museum confirmed its network was compromised a month after the initial detection.
- Exposed data may include names, dates of birth, Social Security numbers, and government ID numbers.
- The breach may also have exposed partial financial data, payment card details, and medical information.
- LACMA notified law enforcement and sent breach notices with identity protection support to affected individuals.